CVE-2013-4732: Digital Alert Systems Dasdec Eas

High severity, CVSS 10.0. EPSS: 3% chance of exploitation in the next 30 days.

The administrative web server on the Digital Alert Systems DASDEC EAS device through 2.0-2 and the Monroe Electronics R189 One-Net EAS device through 2.0-2 uses predictable session ID values, which makes it easier for remote attackers to hijack sessions by sniffing the network. NOTE: VU#662676 states "Monroe Electronics could not reproduce this finding.

Affected products

  • Digital Alert Systems Dasdec Eas: up to and including 2.0-2; version 2.0-0 only; version 2.0-1 only
  • Monroe Electronics r189 One-Net Eas: up to and including 2.0-2; version 2.0-0 only; version 2.0-1 only

Published 2013-06-30. Last modified 2026-06-16.